consumerweb-calurls@99.9.1
Malicious code in consumerweb-calurls (npm)
Analysis
consumerweb-calurls@99.9.1 is a dependency-confusion package that installs a remote tarball from an external URL as a dependency. The package itself is an empty stub (module.exports = {}), but its dependencies field points to hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]5[.]6[.]tgz. When npm installs this package, it fetches and installs the remote tarball, which can execute arbitrary code during installation or at runtime. The high version number (99.9.1) and combosquat name (mimicking an internal/private package) are characteristic of dependency-confusion attacks designed to be preferred over legitimate internal packages.
- analyzed by
- Leitwacht
- first seen
- Jul 21, 2026, 05:07 AM
- analyzed
- Jul 21, 2026, 05:08 AM
Related advisories
- consumerweb-creditcollection@99.9.1
- cxpw-offers@99.9.1
- app-data-ist@2.1.6
- requestor-util@99.9.1
- @dreamguyxeon/libsignal-node@1.0.1
- topk-js@0.12.0
- json-validator-utils@1.0.1
- habingeer@2.1.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.